QID 87516
Date Published: 2022-08-22
QID 87516: SAP NetWeaver AS for Java Information Disclosure Vulnerability
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure.
Affected Versions
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploit may lead to Sensitive Information Disclosure
Solution
Customers are advised to follow the SAP Security Advisory for remediation instructions.
Vendor References
CVEs related to QID 87516
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2826528 |
|